bridges: strip client Authorization at the Route - #44
Merged
Merged
Conversation
Every client aperture-cli launches sends a placeholder bearer because its SDK refuses to build a request without one. A gateway that treats the header as authoritative rejects it with a 401, which is the Solar Winds failure. Ingress auth at the Aperture is the Machine's tailnet identity and every upstream auth mode either replaces or strips the client header, so dropping it at the Route is safe and fixes all clients at once.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Drops the
Authorizationheader in the Route's proxy director before a request leaves for Aperture.Every client launched sends a placeholder bearer (
not-needed,-, whatever its SDK accepts) because the SDK refuses to build a request without one. Ingress auth at Aperture is the machine's tailnet identity, so the header is never actually used. A gateway that treats it as authoritative rejects it with a 401. Stripping it once at the Route fixes every client at the same time rather than hunting for a placeholder each gateway tolerates.